Analytics BIOC Low

Uncommon creation or access operation of sensitive shadow copy

An uncommon creation or access of a sensitive Shadow Copy volume path.

Module:
Platform Analytics
Data source:
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: OS Credential Dumping (T1003)
Attacker's goals:

Attackers may try to copy sensitive data or dump OS credentials from the host file system by using Shadow Copy volume utilities.

Investigative actions:

Verify if the shadow copy operation is part of an IT activity. Look for other hosts performing the same shadow copy event with similar causality process behavior.* Inspect the causality process and its characteristics as they appear on other hosts.

Test period:
N/A (single event)
Deduplication:
1 Day
2 variations:
  • Uncommon creation or access operation of sensitive shadow copy by a remote actor Low
  • Uncommon creation or access operation of sensitive shadow copy by a high-risk process High (parent: Low)